Skip to main content
buildradar
Sign in
Topic · bugbounty

bugbounty

Tracked open-source repos tagged bugbounty, sorted by stars.

157 repos
  • BurpBounty@wagiro

    Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.

    1,813+2Star change over the last 7 days
  • inql@doyensec

    InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

    1,804+2Star change over the last 7 days
  • gotestwaf@wallarm

    An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

    1,800+1Star change over the last 7 days
  • wordlists@trickest

    Real-world infosec wordlists, updated regularly

    1,792+1Star change over the last 7 days
  • metlo@metlo-labs

    Metlo is an open-source API security platform.

    1,783+0Star change over the last 7 days
  • metabigor@j3ssie

    OSINT power without API key hassle

    1,755+19Star change over the last 7 days
  • A big list of Android Hackerone disclosed reports and other resources.

    1,710+2Star change over the last 7 days
  • urlhunter@utkusen

    a recon tool that allows searching on URLs that are exposed via shortener services

    1,697+0Star change over the last 7 days
  • BruteForceAI@MorDavid

    Advanced LLM-powered brute-force tool combining AI intelligence with automated login attacks

    1,690+6Star change over the last 7 days
  • A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

    1,677+2Star change over the last 7 days
  • A collection of one-liners for bug bounty hunting.

    1,630+1Star change over the last 7 days
  • inventory@trickest

    Asset inventory of over 800 public bug bounty programs.

    1,604+1Star change over the last 7 days
  • ScopeSentry@Autumn-27

    ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed nodes

    1,601+9Star change over the last 7 days
  • subzy@PentestPad

    Subdomain takeover vulnerability checker

    1,591+1Star change over the last 7 days
  • GooFuzz@m3n0sd0n4ld

    GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking).

    1,583-1Star change over the last 7 days
  • Awesome Vulnerable Applications

    1,477+5Star change over the last 7 days
  • burp-ai-agent@six2dez

    Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

    1,477+40Star change over the last 7 days
  • AWSBucketDump@jordanpotti

    Security Tool to Look For Interesting Files in S3 Buckets

    1,473+0Star change over the last 7 days
  • git-hound@tillson

    Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

    1,454+2Star change over the last 7 days
  • API Security Project aims to present unique attack & defense methods in API Security field

    1,447+1Star change over the last 7 days
  • bruteforce-lists@random-robbie

    Some files for bruteforcing certain things.

    1,427+0Star change over the last 7 days
  • A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains. Join us to explore, contribute, and enhance your hacking toolkit!

    1,383+1Star change over the last 7 days
  • google-dorks@Proviesec

    Useful Google Dorks for WebSecurity and Bug Bounty

    1,363+6Star change over the last 7 days
  • vapi@roottusk

    vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

    1,349+0Star change over the last 7 days
  • public-bugbounty-programs@projectdiscovery

    Community curated list of public bug bounty and responsible disclosure programs.

    1,342+1Star change over the last 7 days
  • PwnFox@yeswehack

    PwnFox is a Firefox/Burp extension that provide usefull tools for your security audit.

    1,340+0Star change over the last 7 days
  • agent@PentesterFlow

    Agentic offensive-security in your terminal

    1,323+7Star change over the last 7 days
  • VHostScan@codingo

    A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.

    1,308-1Star change over the last 7 days
  • Interlace@codingo

    Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.

    1,303+0Star change over the last 7 days
  • go-dork@dwisiswant0

    The fastest dork scanner written in Go.

    1,302+0Star change over the last 7 days
← Back to topics